Legal
Privacy Policy
What personal data we collect about you as a customer, why, and what rights you have over it.
This document is in preparation. It is not yet in force.
Below is the structure the final text will cover, published so you can see what will be in it. We have deliberately not filled it with generated legal wording — text that reads like a contract and binds nobody is worse than an honest gap. If you need the current draft for a review, email sales@securive.net.
Who we are and how to reach us
Controller identity, registered address, and the contact route for privacy questions.
What we collect
Account details, billing details, and service telemetry. Backup content is customer data processed under the DPA, not personal data we collect for our own purposes — the distinction matters and must be explicit.
Why we process it, and the lawful basis
Contract performance for the service, legitimate interests for security and abuse prevention, consent where consent is genuinely the basis.
Cookies and tracking
The site currently loads no third-party analytics or advertising scripts. If that changes, this section and a consent mechanism change with it — see lib/analytics.ts.
Who we share it with
Sub-processors by category and purpose, with a maintained list. Never sold, and that should be stated in those words.
International transfers
Where data goes and the mechanism relied on. Should reconcile with the residency guarantees on /security.
How long we keep it
Retention periods by data category, and what triggers deletion.
Your rights
Access, correction, erasure, portability, objection — and the actual process for exercising them, with a response time.
Security
A summary that points at /security rather than duplicating it, so the two can't drift apart.
Changes to this policy
How changes are notified, and a version history so a reader can see what changed.